Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | VMware VMXNET3ÕûÊýÒç¶Âí½Å |
CVE ID | CVE-2025-41236 |
·ì϶ÀàÐÍ | ÕûÊýÒç³ö | ·¢ÏÖ¹¦·ò | 2025-07-17 |
·ì϶ÆÀ·Ö | 9.3 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ±¾µØ | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
VMXNET3ÊÇVMwareÌṩµÄ¸ß»úÄÜÐé¹¹ÍøÂçÊÊÅäÆ÷£»VMCI£¨Virtual Machine Communication Interface£©ÓÃÓÚÐé¹¹»úÓëËÞÖ÷»úÖ®¼äµÄ¸ßЧͨѶ£»PVSCSIÊÇÃæÏò¸ß»úÄÜ´æ´¢µÄÐé¹¹»¯SCSI½ÚÔìÆ÷£»vSocketsÌṩÐé¹¹»úÓëËÞÖ÷»ú»òÐé¹¹»úÖ®¼äµÄÌ×½Ó×ÖͨѶ»úÔ죬ÓÃÓÚµÍÑÓ³¤Êý¾Ý´«Êä¡£
2025Äê7ÔÂ17ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½VMware¹Ù·½Åû¶Æä¶à¸ö²úÆ·ÖдæÔÚËĸö¸ßΣ·ì϶£¬Éæ¼°VMXNET3¡¢VMCI¡¢PVSCSIºÍvSocketsµÈ¹Ø¼üÐé¹¹»¯×é¼þ£¬±ðÀëΪVMware VMXNET3ÕûÊýÒç¶Âí½Å£¨CVE-2025-41236£©¡¢VMware VMCIÕûÊýÏÂÒç·ì϶£¨CVE-2025-41237£©¡¢VMware PVSCSI¶ÑÒç¶Âí½Å£¨CVE-2025-41238£©ÒÔ¼°VMware vSocketsÐÅϢй¶·ì϶£¨CVE-2025-41239£©¡£ÆäÖУ¬Ç°Èý¸ö·ì϶¿É±»¾ß±¸±¾µØÖÎÀíԱȨÏ޵Ĺ¥»÷ÕßÔÚÐé¹¹»úÄÚÀûÓã¬×îÖÕÒÔVMX¹ý³ÌȨÏÞÔÚËÞÖ÷»úÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬ÑϳÁÍþвÐé¹¹»¯Æ½Ì¨µÄϵͳ°²È«£»CVE-2025-41239ÔòÓÉÓÚvSockets×é¼þ´æÔÚδ³õʼ»¯ÄÚ´æÊ¹ÓÃÎÊÌ⣬¿ÉÄܵ¼Ö¹¥»÷Õßй¶ÓëÆäͨѶ¹ý³ÌµÄÃô¸ÐÄÚ´æÐÅÏ¢¡£
¶þ¡¢Ó°ÏìÁìÓò
VMware Cloud Foundation ESX = 9.0.0.0 VMware Workstation = 17.x VMware Cloud Foundation = 4.5.x VMware Cloud Foundation = 5.x VMware Telco Cloud Platform = 2.x VMware Telco Cloud Platform = 3.x VMware Telco Cloud Platform = 4.x VMware Telco Cloud Platform = 5.x VMware Telco Cloud Infrastructure = 2.x VMware Telco Cloud Infrastructure = 3.x
CVE-2025-41237Ó°ÏìÁìÓò
VMware vSphere Foundation ESX = 9.0.0.0VMware Workstation = 17.xVMware Cloud Foundation ESX = 9.0.0.0VMware Cloud Foundation = 4.5.xVMware Cloud Foundation = 5.xVMware Telco Cloud Platform = 2.xVMware Telco Cloud Platform = 3.xVMware Telco Cloud Platform = 4.xVMware Telco Cloud Platform = 5.xVMware Telco Cloud Infrastructure = 2.xVMware Telco Cloud Infrastructure = 3.x
CVE-2025-41238Ó°ÏìÁìÓò
VMware Cloud Foundation ESX = 9.0.0.0VMware Workstation = 17.xVMware Cloud Foundation = 4.5.xVMware Cloud Foundation = 5.xVMware Telco Cloud Platform = 2.xVMware Telco Cloud Platform = 3.xVMware Telco Cloud Platform = 4.xVMware Telco Cloud Platform = 5.xVMware Telco Cloud Infrastructure = 2.xVMware Telco Cloud Infrastructure = 3.x
CVE-2025-41239Ó°ÏìÁìÓò
VMware Cloud Foundation ESX = 9.0.0.0VMware vSphere Foundation ESX = 9.0.0.0VMware Cloud Foundation VMware Tools for Windows = 13.0.0.0VMware vSphere Foundation VMware Tools for Windows = 13.0.0.0VMware Workstation = 17.xVMware Cloud Foundation = 4.5.xVMware Cloud Foundation = 5.xVMware Telco Cloud Platform = 2.xVMware Telco Cloud Platform = 3.xVMware Telco Cloud Platform = 4.xVMware Telco Cloud Platform = 5.xVMware Telco Cloud Infrastructure = 2.xVMware Telco Cloud Infrastructure = 3.xVMware Tools for Windows = 11.x.xVMware Tools for Windows = 12.x.xVMware Tools for Windows = 13.x.xVMware Tools for Linux = 11.x.xVMware Tools for Linux = 12.x.xVMware Tools for Linux = 13.x.xVMware Tools for macOS = 11.x.xVMware Tools for macOS = 12.x.xVMware Tools for macOS = 13.x.x
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
¹Ù·½ÒѰ䲼½¨¸´°æ±¾£¬½¨Ò龡¿ìÉý¼¶ÖÁ×îа汾VMware vSphere Foundation ESX 9.0.0.0 Éý¼¶ÖÁESXi-9.0.0.0100-24813472VMware Tools 13.0.0.0£¨Windows£©Éý¼¶ÖÁ13.0.1.0VMware ESXi 8.0£ºÉý¼¶ÖÁESXi80U3f-24784735»òÉý¼¶ÖÁESXi80U2e-24789317VMware ESXi 7.0£ºÉý¼¶ÖÁESXi70U3w-24784741VMware Workstation 17.x£ºÉý¼¶ÖÁ 17.6.4VMware Fusion 13.xÉý¼¶ÖÁ13.6.4VMware Cloud Foundation°æ±¾ 5.x£ºÒì²½²¹¶¡ÖÁESXi80U3f-24784735VMware Cloud Foundation°æ±¾ 4.5.x£ºÒì²½²¹¶¡ÖÁESXi70U3w-24784741VMware Telco Cloud Platform°æ±¾ 5.x / 4.x£ºÉý¼¶ÖÁESXi80U3f-24784735VMware Telco Cloud Platform°æ±¾ 3.x / 2.x£ºÉý¼¶ÖÁESXi70U3w-24784741VMware Telco Cloud Infrastructure£¨3.x / 2.x£©Éý¼¶ÖÁESXi70U3w-24784741VMware Tools Windows 13.xx£ºÉý¼¶ÖÁ13.0.1.0VMware Tools Windows 12.xx / 11.xx£ºÉý¼¶ÖÁ12.5.3
ÏÂÔØÁ´½Ó£º
VMware Cloud Foundation 9.0.0.0.0https://support.broadcom.com/group/ecx/productfiles?displayGroup=VMware%20Cloud%20Foundation%209&release=9.0.0.0&os=&servicePk=&language=EN&groupId=529537&viewGroup=true
VMware vSphere Foundation 9.0.0.0.0
https://support.broadcom.com/group/ecx/productfiles?displayGroup=VMware%20vSphere%20Foundation%209&release=9.0.0.0&os=&servicePk=&language=EN&groupId=529542&viewGroup=true
VMware ESXi 8.0 ESXi80U3f-24784735
https://support.broadcom.com/web/ecx/solutiondetails?patchId=15938https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/release-notes/esxi-update-and-patch-release-notes/vsphere-esxi-80u3f-release-notes.html
VMware ESXi 8.0 ESXi80U2e-24789317
https://support.broadcom.com/web/ecx/solutiondetails?patchId=15939https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/release-notes/esxi-update-and-patch-release-notes/vsphere-esxi-80u2e-release-notes.html
VMware ESXi 7.0 ESXi70U3w-24784741
https://support.broadcom.com/web/ecx/solutiondetails?patchId=15940https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/7-0/release-notes/esxi-update-and-patch-release-notes/vsphere-esxi-70u3w-release-notes.html
VMware Workstation 17.6.4
https://support.broadcom.com/group/ecx/productdownloads?subfamily=VMware%20Workstation%20Pro&freeDownloads=truehttps://techdocs.broadcom.com/us/en/vmware-cis/desktop-hypervisors/workstation-pro/17-0/release-notes/vmware-workstation-1764-pro-release-notes.html
VMware Fusion 13.6.4
https://support.broadcom.com/group/ecx/productdownloads?subfamily=VMware%20Fusion&freeDownloads=truehttps://techdocs.broadcom.com/us/en/vmware-cis/desktop-hypervisors/fusion-pro/13-0/release-notes/vmware-fusion-1364-release-notes.html
VMware Cloud Foundation 5.x, 4.5.x
https://knowledge.broadcom.com/external/article?legacyId=88287
VMware Tools 13.0.1.0
https://support.broadcom.com/group/ecx/productfiles?subFamily=VMware%20Tools&displayGroup=VMware%20Tools%2013.x&release=13.0.1.0&os=&servicePk=&language=EN&freeDownloads=truehttps://techdocs.broadcom.com/us/en/vmware-cis/vsphere/tools/13-0-0/release-notes/vmware-tools-1301-release-notes.html
VMware Tools 12.5.3
https://support.broadcom.com/group/ecx/productfiles?subFamily=VMware%20Tools&displayGroup=VMware%20Tools%2012.x&release=12.5.3&os=&servicePk=&language=EN&freeDownloads=truehttps://techdocs.broadcom.com/us/en/vmware-cis/vsphere/tools/12-5-0/release-notes/vmware-tools-1253-release-notes.html
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
?¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£?¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£?ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£?¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£?ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/35877